Agent skill

Triage Snmp Diagnostics

by netdata in netdata/netdata

Investigate captured SNMP diagnostics and support bundles, or review diagnostics-tool and evidence-interpretation changes.

GPL-3.0Auto-check passedDevOps & Cloud

Install Triage Snmp Diagnostics

skills CLI
$ npx skills add netdata/netdata --skill triage-snmp-diagnostics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install netdata/netdata triage-snmp-diagnostics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/triage-snmp-diagnostics .claude/skills/triage-snmp-diagnostics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
triage-snmp-diagnostics
GitHub stars
81k
Token cost
~3k tokens
SKILL.md length
1,244 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
GPL-3.0

At a glance

Investigate captured SNMP diagnostics and support bundles, or review diagnostics-tool and evidence-interpretation changes.

  • Works in 4 steps: Identify the reported symptom, affected… → Keep reports under… → Use list for a directory or bundle and… → …
  • DevOps & Cloud work in your project
  • SKILL.md covers Select The Operation, Owners, Establish The Evidence Window and Choose The Investigation, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Triage Snmp Diagnostics is an agent skill from netdata/netdata. Investigate captured SNMP diagnostics and support bundles, or review diagnostics-tool and evidence-interpretation changes. Covers missing topology/metrics/BGP/licensing, slow collection, and discovery/lifecycle failures through offline inspection, replay and source tracing. Live queries, traps and collector/profile implementation use separate skills.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. The repository describes itself as: The fastest path to AI-powered full stack observability, even for lean teams. The licence is GPL-3.0.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/triage-snmp-diagnostics”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify the reported symptom, affected device/link or metric, expected behavior, and incident time. Start inventory
  2. Keep reports under /.local/audits/snmp-diagnostics// with private permissions. Preserve the supplied
  3. Use list for a directory or bundle and read both collection notes and component errors. With an individual file,
  4. Record producer version, run, capture times, and selected checkpoint/device alongside the report. Check whether they

What it can do on your machine

Read from SKILL.md and the folder at commit 2c378f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Triage Snmp Diagnostics loads about 3k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 1,244 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from netdata/netdata at commit 2c378f0, republished under its GPL-3.0 licence (© netdata). 1,244 words, ~2,983 tokens.

Download SKILL.mdSave it as .claude/skills/triage-snmp-diagnostics/SKILL.md (or your agent's skills folder).
name
triage-snmp-diagnostics
description
Investigate captured SNMP diagnostics and support bundles, or review diagnostics-tool and evidence-interpretation changes. Covers missing topology/metrics/BGP/licensing, slow collection, and discovery/lifecycle failures through offline inspection, replay and source tracing. Live queries, traps and collector/profile implementation use separate skills.

Offline SNMP Diagnostics

Developer workflow for investigating captured SNMP evidence with the repository's maintainer tool. Start with the supplied evidence and narrow the failure to acquisition, processing, or the consuming feature before proposing a fix.

Select The Operation

TaskUse this workflow
Investigate a supplied captureEstablish the evidence window below, then select the symptom and owner sections
Review diagnostics tooling or interpretation changesRead the affected input, evidence, replay and resource-cost contracts from the owners below; assess the diff and existing fixtures/validation
Explain an evidence field or limitationRead its owner section and relevant producer source; no capture run required solely to explain the contract

Source-only review does not require acquiring a support bundle, replaying private data or creating investigation artifacts. Report material evidence gaps without treating loading this skill as authorization for operational steps. A review of unrelated SNMP collector internals does not select this skill unless diagnostic evidence/contracts are affected.

Owners

Read the sections needed for the current symptom; command and format details belong to these owners.

Owner sectionSubject
src/go/tools/snmp-diagnostics/README.md#input-selectionSupported inputs and evidence selectors
src/go/tools/snmp-diagnostics/README.md#collection-status-and-partial-listingsInventory and partial collection interpretation
src/go/tools/snmp-diagnostics/README.md#normal-device-evidenceMetrics, BGP, licensing, and source-reference interpretation
src/go/tools/snmp-diagnostics/README.md#topology-replay-and-inspectionDevice/link inspection and replay queries
src/go/tools/snmp-diagnostics/README.md#read-limits-and-container-costSelected-document limits and repeated bundle reads
src/go/tools/snmp-diagnostics/README.md#collection-costAcquisition timing and accounting limits
src/go/plugin/go.d/collector/snmp_topology/ARCHITECTURE.md#diagnostic-files-and-publicationPublication cadence, retention, runs, and terminal behavior
src/go/plugin/go.d/collector/snmp_topology/ARCHITECTURE.md#offline-diagnostic-inspectionCapture branches and stage availability
src/go/plugin/go.d/collector/snmp_topology/ARCHITECTURE.md#portable-archive-codec-and-replay-boundaryCaptured inputs and replay boundary
docs/developer-and-contributor-corner/netdata-support-bundle.md#what-it-collectsCompanion logs, configuration, and bundle inventory
docs/developer-and-contributor-corner/netdata-support-bundle.md#privacy-and-sanitizationSanitization boundaries
docs/developer-and-contributor-corner/netdata-support-bundle.md#include-snmp-diagnosticsOperator capture instructions

For live API evidence, use query-netdata-agents or query-netdata-cloud. For received traps, use query-snmp-traps. When the investigation leads to implementation, route collector changes through collectors-authoring, profile changes through collectors-snmp-profiles, and topology producer changes through topology-authoring.

Establish The Evidence Window

  1. Identify the reported symptom, affected device/link or metric, expected behavior, and incident time. Start inventory even if some incident details are missing; ask only for details that change the investigation.
  2. Keep reports under <repo>/.local/audits/snmp-diagnostics/<case>/ with private permissions. Preserve the supplied archive. Raw inspections and replay output MUST NOT enter committed fixtures, public issues, or review prompts.
  3. Use list for a directory or bundle and read both collection notes and component errors. With an individual file, start with validate and summary. For containers, select and validate the relevant document after inventory.
  4. Record producer version, run, capture times, and selected checkpoint/device alongside the report. Check whether they cover the incident before interpreting the data. Follow the publication owner for retention and freshness semantics; do not assume the bundle is one synchronized sample.

Run the CLI from src/go as shown in its README. For repeated commands, building the same tool into the private case folder avoids repeated compilation. Choose the evidence scope before requesting full inspections; consult the container cost owner before scanning a large tar repeatedly.

Choose The Investigation

SymptomStart withFollow the evidence
Missing/wrong topology device or linkTopology summary, then inspect-device or inspect-linkCaptured protocol observations → graph membership → rendered actor/link; use replay to locate an existing link.
Missing/wrong metricNormal device summary, then inspect-deviceSelected profile and acquisition results → processed metric and emission decision → sample value.
Missing/stale BGP peer or wrong peer stateNormal device inspectionProfile BGP rows and source operations → peer cache and refresh outcome. For a missing topology BGP edge, use the topology path too.
Missing/wrong license inventory or usageNormal device inspectionProfile license rows and source operations → normalized licensing state.
Discovery, initialization, or missing device evidenceLifecycle summaryCandidate/runtime state and failure → available device cuts → matching logs/configuration.
Slow SNMP collectionThe affected collector's device inspectionNormal attempt timestamps and referenced operation timing, or topology collection contexts and detailed accounting; use the collection-cost owner for Handler timing limits.

Topology summaries identify registrations. For normal evidence, select a run from the listing and identify the device from its normal summary; a lifecycle inventory can help only after its producer run matches. Do not require a topology checkpoint to investigate normal metrics, BGP, or licensing.

Explain The Collector Result

Once inspection locates the affected stage, read only the relevant subsystem details:

QuestionOwner sections
Why this profile or value?src/go/plugin/go.d/collector/snmp/ARCHITECTURE.md#profile-selection, src/go/plugin/go.d/collector/snmp/profile-format.md#1-selector, src/go/plugin/go.d/collector/snmp/profile-format.md#2-extends, src/go/plugin/go.d/collector/snmp/profile-format.md#value-transformation
Why a missing, combined, or derived sample?src/go/tools/snmp-diagnostics/README.md#acquisition-processing-and-samples, src/go/plugin/go.d/collector/snmp/ARCHITECTURE.md#metric-emission, src/go/plugin/go.d/collector/snmp/profile-format.md#virtual-metrics, src/go/plugin/go.d/collector/snmp/profile-format.md#chart-metadata
Were these inputs refreshed?src/go/tools/snmp-diagnostics/README.md#cached-inputs-and-earlier-outcomes
Why this BGP peer state or licensing result?src/go/plugin/go.d/collector/snmp/ARCHITECTURE.md#bgp-collection-and-retained-rows, src/go/plugin/go.d/collector/snmp/ARCHITECTURE.md#licensing-normalization-and-collection-results, src/go/tools/snmp-diagnostics/README.md#cached-state-versus-function-output
Why these topology observations or refresh state?src/go/plugin/go.d/collector/snmp/profile-format.md#41-topology, src/go/plugin/go.d/collector/snmp_topology/ARCHITECTURE.md#topology-profile-composition, src/go/plugin/go.d/collector/snmp_topology/ARCHITECTURE.md#refresh-loop
Why was a topology actor/link changed or filtered?src/go/plugin/go.d/collector/snmp_topology/ARCHITECTURE.md#graph-build-order

These sections identify consumer source symbols where code inspection is needed.

Show full SKILL.md (504 more words)Show less

Trace And Compare

  • Work from the affected output back to its recorded inputs. Inspect the relevant profile, row, metric, or peer before expanding to all source operations. Follow source references using the normal-evidence owner; retain their context with any quoted result so another maintainer can reproduce the join.
  • Separate latest attempts, retained failures/successes, and cached inputs using their own times. Resolve a stale value to its recorded source before attributing it to the latest refresh. Follow the inspection owner when a stage is unavailable; missing evidence is not proof that the device did not return data.
  • Compare retained topology checkpoints with identical query controls. Match device identity and producer context before comparing registrations; obtain link selectors from each replay instead of carrying a row index across cuts. Use previous-run normal evidence only when it helps the incident, with the run boundaries made explicit.
  • Distinguish profile/acquisition failures from processing and consumer decisions. A captured sample alone does not settle whether a chart was created or displayed; use the normal-evidence owner to bound that conclusion.
  • For a source-level explanation, check the producer version against the code being read. Treat replay through a different checkout as a version-qualified experiment. Do not edit captured values to make a replay succeed.
  • For discovery targets, collector enablement, polling settings, or profile overrides, inspect relevant files under 04-config/ and persisted UI/API configuration under 06-state/dyncfg/, when available. Compare them with the diagnostic evidence; persisted configuration may differ from what the collector used at capture time.

Correlate Companion Logs

  • After establishing the evidence timeline, use the bundle inventory to find relevant logs and configuration. Prioritize available 05-logs/collector.log, 05-logs/journal-netdata.txt, and 05-logs/journal-namespace-netdata.txt; an empty collector log is not a reason to skip the journals.
  • Use ordinary archive/text tools for logs. Start with SNMP matches, narrow using collector=snmp, collector=snmp_topology, and the affected job where present, then inspect nearby context. Include relevant go.d startup, shutdown, discovery, and job messages; do not restrict the search to warnings/errors or treat every SNMP match as a collector failure (alerts can also match).
  • Correlate message times, jobs, and restarts with the incident and diagnostic capture/run boundaries. Consult the bundle's sanitization owner before joining identifiers: differently sanitized files may not share literal device names.
  • Check log coverage and collection notes before interpreting missing matches; capped captures, missing history, and rate-limited messages cannot establish that no failure occurred. Keep conclusions within the captured window.

Report The Finding

Report the symptom and evidence coverage, then the supported failure location and its consequence. Cite the selected file or checkpoint, producer/run and capture time, and the relevant inspection branch or source reference. Separate observations from hypotheses and state what the capture cannot establish.

Recommend the smallest useful next check when evidence is insufficient, explaining which uncertainty it resolves. Use the operator capture owner when another bundle is needed; do not silently replace offline analysis with live SNMP polling, configuration changes, or sharing raw reports. When a fix is justified, hand the evidence and reproduction to the appropriate authoring skill rather than embedding an implementation workflow here.

© netdata, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/triage-snmp-diagnostics of netdata/netdata.

Open the folder on GitHubat commit 2c378f0

Compare with similar skills

Triage Snmp Diagnostics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Triage Snmp Diagnostics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Triage Snmp Diagnostics this skillnetdata/netdata81k—~3kAutomated safety check: PassGPL-3.0
Monitor CInrwl/nx29k6 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw35k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k9 repos~4.3kAutomated safety check: PassNone
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 6 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    35k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 9 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub starsUsed in 1 repo~3.1k tokens
    DevOps & CloudAuto-check passed

More from netdata/netdata

All 27 skills in this repo
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Repo Mirror Sources

    netdata/netdata

    Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.

    81k GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Triage Agent Events

    netdata/netdata

    Investigate Netdata crashes, panics and fatals from agent-events captures or authorized fleet queries.

    81k GitHub stars~2.4k tokensUpdated today
    Auto-check: notes
  • Triage Codacy

    netdata/netdata

    Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers.

    81k GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • Triage Coverity

    netdata/netdata

    Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested.

    81k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Triage Sonarqube

    netdata/netdata

    Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.

    81k GitHub stars~2.8k tokensUpdated today
    Auto-check: notes

Categories

Questions about Triage Snmp Diagnostics

What does Triage Snmp Diagnostics do?

Investigate captured SNMP diagnostics and support bundles, or review diagnostics-tool and evidence-interpretation changes. Triage Snmp Diagnostics is an agent skill from netdata/netdata. Investigate captured SNMP diagnostics and support bundles, or review diagnostics-tool and evidence-interpretation changes.

When should I use Triage Snmp Diagnostics?

Triage Snmp Diagnostics fits situations like: devOps & Cloud work in your project.

How do I install Triage Snmp Diagnostics in Claude Code?

Run `npx skills add netdata/netdata --skill triage-snmp-diagnostics -a claude-code`. Or copy the skill folder (.agents/skills/triage-snmp-diagnostics in netdata/netdata) into .claude/skills/triage-snmp-diagnostics in your project. Claude Code loads it when a task matches its description.

How do I install Triage Snmp Diagnostics in Codex?

Run `npx skills add netdata/netdata --skill triage-snmp-diagnostics -a codex`. Or copy the skill folder (.agents/skills/triage-snmp-diagnostics in netdata/netdata) into .agents/skills/triage-snmp-diagnostics in your project. Codex loads it when a task matches its description.

Can I use Triage Snmp Diagnostics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add netdata/netdata --skill triage-snmp-diagnostics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triage-snmp-diagnostics, .gemini/skills/triage-snmp-diagnostics, .github/skills/triage-snmp-diagnostics and .opencode/skills/triage-snmp-diagnostics in your project.

What does Triage Snmp Diagnostics need to run?

SKILL.md names no scripts, command-line tools or credentials: Triage Snmp Diagnostics is instructions for the agent only.

Does Triage Snmp Diagnostics access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Triage Snmp Diagnostics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Triage Snmp Diagnostics use?

Triage Snmp Diagnostics is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Triage Snmp Diagnostics use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Triage Snmp Diagnostics?

Skills that share tags, products or a category with Triage Snmp Diagnostics: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 35k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Openclaw Live Updater (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Triage Snmp Diagnostics?

netdata (a GitHub organization) maintains it in netdata/netdata, which has 80,838 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 8, 2026.

Source: netdata/netdata on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.